Service impact when disabling network resources using ddos protection

박새진 20 Reputation points
2023-09-11T04:38:47.3333333+00:00

I am curious if there will be a problem with the existing service when unprotecting a network resource protected by ddos protection.

Azure DDos Protection
Azure DDos Protection
An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
71 questions
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 49,651 Reputation points Microsoft Employee
    2023-09-11T05:54:41.44+00:00

    Hello @박새진 ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you would like to know if there will be any problem with your existing service when disabling/removing a network resource from DDOS protection.

    No, there will be no service impact on the resources. You can disable DDOS protection for a virtual network or for a Public IP address (depending on the SKU you are using).

    The only thing to keep in mind is when changing DDoS IP protection from Enabled to Disabled, telemetry for that resource will no longer be active.

    Refer: https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection#disable-for-a-virtual-network

    https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-ip-protection-portal#disable-for-a-public-ip-address

    https://learn.microsoft.com/en-us/azure/ddos-protection/telemetry

    Another thing to note here: Disabling DDoS protection for a public IP address is currently a preview feature. If you disable DDoS protection for a public IP resource that is linked to a virtual network with an active DDoS protection plan, you'll still be billed for DDoS Network Protection. However, the following functionalities will be suspended: mitigation of DDoS attacks, telemetry, and logging of DDoS mitigation events.

    Refer: https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-protection-sku-comparison#limitations

    Even when a resource is removed from DDOS Protection, it is inherently protected by the default infrastructure-level DDoS protection but the protection that safeguards the infrastructure has a much higher threshold than most applications have the capacity to handle and does not provide telemetry or alerting.

    Refer: https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-faq#are-services-unsafe-in-azure-without-the-service-

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.